Also: Phishing attacks are getting scarily sophisticated. What to watch for But it can be extremely difficult to detect or remove spyware once it’s implanted in a device. This guide will run through different forms of malicious software that could end up on your iOS or Android handset, what the warning signs of infection are, and how to remove such pestilence from your mobile devices if it is possible to do so.  We will also touch upon stalkerware and other ways threats closer to home may spy on you – and what you can do about it.

How to find and remove spyware from your iPhone or Android

Also: How tech is a weapon in modern domestic abuse – and how to protect yourself Nuisanceware is often bundled with legitimate apps. It interrupts your web browsing with pop-ups, changes your homepage or search engine settings, and may also gather your browsing data in order to sell it off to advertising agencies and networks.  Although considered malvertising, nuisanceware is generally not dangerous or a threat to your core security. Instead, these malware packages are focused on illicit revenue generation by infecting machines and creating forced ad views or clicks. Also: How to protect and secure your password manager There’s also basic spyware. These generic forms of malware steal operating system and clipboard data and anything of potential value, such as cryptocurrency wallet data or account credentials. Spyware isn’t always targeted and may be used in general phishing attacks.  Spyware may land on your device through phishing, malicious email attachments, social media links, or fraudulent SMS messages. Advanced spyware, also known as stalkerware, is a step up. Unethical and sometimes dangerous, this malware is sometimes found on desktop systems, but it is now most commonly implanted on phones. Spyware and stalkerware may be used to monitor emails and SMS and MMS messages sent and received; to intercept live calls for the purpose of eavesdropping across standard telephone lines or Voice over IP (VoIP) applications; to covertly record environmental noise or take photos; to track victims via GPS; or to hijack social media apps such as Facebook and WhatsApp. They may also include keylogging features. Stalkerware is typically used to spy on someone as an individual and watch what they do, say, and where they go. Stalkerware is commonly linked to cases of domestic abuse.  You then have government-grade commercial spyware. Pegasus is the most well-known recent case, sold as a tool to governments for combating terrorism and for law enforcement purposes – it ultimately was found on smartphones belonging to journalists, activists, political dissidents, and lawyers.  In November 2022, the Google Threat Analysis Group (TAG) published details on Heliconia, a new commercial spyware framework with a potential link to a private Spanish company. The same goes for SMS messages, too, which may contain links to trick you into unwittingly downloading malware.  Also: This notorious ransomware has now found a new target To catch a victim unaware, these phishing messages will lure you into clicking a link or executing software that hosts a spyware or stalkerware payload. If the malware is being loaded remotely, user interaction is required, and so these messages might try to panic you – such as by demanding payment to a tax office or bank, or pretending to be a failed delivery notice. Messages could potentially use spoofed addresses from a contact you trust, too. For example, during the COVID-19 pandemic, scammers sent messages offering vaccination appointments. Victims would click on a malicious link and either unwittingly download spyware or malware, or would hand over personal information by filling in fake request forms.   When it comes to stalkerware, initial infection messages may be more personal and tailored to the victim.  Physical access or the accidental installation of spyware by the victim is necessary. However, it can take less than a minute to install some variants of spyware and stalkerware. If your phone goes missing or has been out of your possession for a time, and reappears with different settings or changes that you do not recognize, this may be an indicator of tampering.

Android

A giveaway on an Android device is a setting that allows apps to be downloaded and installed outside of the official Google Play Store.  If enabled, this may indicate tampering and jailbreaking without consent. Not every form of spyware and stalkerware requires a jailbroken device, though. This setting is found in most modern Android builds in Settings > Security > Allow unknown sources. (This varies depending on device and vendor.) You can also check Apps > Menu > Special Access > Install unknown apps to see if anything appears that you do not recognize, but there is no guarantee that spyware will show up on the app list. Some forms of spyware will also use generic names and icons to avoid detection. For example, they may appear to be a useful utility app such as a calendar, calculator, or currency converter. If a process or app comes up on the app list that you are not familiar with, a quick search online may help you find out whether it is legitimate.

iOS 

iOS devices that aren’t jailbroken are generally harder to install malware on unless an exploit for a zero-day or unpatched vulnerability is used against you, but the same malware principles apply – with the right tool, exploit, or software, your device could be compromised either with physical access or remotely. You may be more susceptible to infection if you have not updated your iPhone’s firmware to the latest version and you do not run frequent antivirus scans. Both iOS and Android phones, however, will typically show symptoms of a malware infection.

Signs that spyware is on your phone

You may experience unexpected handset battery drain, overheating, and strange behavior from the device’s operating system or apps. Settings such as GPS and location functions may unexpectedly turn on or you may see random reboots. If you are suddenly using far more data than normal, this could be an indication that information is being sent from your smartphone or remote connections are active. You may also have trouble turning off your device fully. Some forms of spyware that are focused on fraudulent revenue generation may be able to secure enough permissions to impact your bank balance. If you are signed up for services or premium SMS plans and you know you didn’t consent to them, this could be a sign that spyware is on your device. Keep an eye on your credit cards for any signs of suspicious payments.  An important point to mention is that sometimes spyware or other forms of malicious software might end up on your device via an originally benign app. There have been cases in the past of developers releasing a genuine, useful app in official repositories, such as a currency converter or weather app, and then after a large user base has been gathered, the developers twist the app’s functions.  Last year, Google removed malicious apps from the Google Play Store that had been masquerading as Bluetooth utilities and had been downloaded by over a million users. While the apps didn’t appear malicious at first, within days, users were bombarded with adverts and pop-ups. When spyware is removed, especially in the case of stalkerware, some operators will receive an alert warning them that the victim’s device has been cleaned up. Should the flow of your information suddenly stop, this would be another clear sign to the observer that the malicious software has been removed.  Do not tamper with your device if you feel your physical safety may be in danger. Instead, reach out to the police and supporting agencies. Now, here are some removal options: Google’s guide to factory-resetting your device can be found here, and Apple has also provided instructions on its support website. Unfortunately, some stalkerware services may survive factory resets. So, failing all of that, consider restoring to factory levels and then throwing your device away. MVT (Mobile Verification Toolkit), an open-source project developed by Amnesty International, is a cyber forensics package able to scan for advanced spyware on mobile devices. However, this is most suited to investigators.

Reboots: Reboot your device daily to prevent persistence from taking hold. The majority of infections have appeared to be based on zero-day exploits with little persistence and so rebooting can hamper attackers.Disable iMessage and FaceTime (iOS): As features enabled by default, iMessage and FaceTime are attractive avenues for exploitation. A number of new Safari and iMessage exploits have been developed in recent years. Use an alternative browser other than Safari or default Chrome: Some exploits do not work well on alternatives such as Firefox Focus. Use a trusted, paid VPN service, and install an app that warns when your device has been jailbroken. Some AV apps will perform this check.  

It is also recommended that individuals who suspect a Pegasus infection make use of a secondary device, preferably running GrapheneOS, for secure communication.  See: How the top VPNs compare; plus, should you try a free VPN? Several years ago, Google removed seven apps from the Play Store that were marketed as employee and child trackers. The tech giant took a dim view of their overreaching functions – including GPS device tracking, access to SMS messages, theft of contact lists, and potentially the exposure of communication taking place in messaging applications. Google has also banned stalkerware ads. However, some apps still apparently slip through the net. Google’s Threat Analysis Group (TAG) is constantly publishing research on new commercial spyware strains and their potential targets. Apple has cracked down on parental control apps, citing privacy-invading functions as the reason for removal. The company offers its own parental device control service called Screen Time for parents who want to limit their child’s device usage. Furthermore, the company does not allow sideloading, a practice Apple says stops mobile threats from proliferating in the iOS ecosystem. In 2022, Apple revealed the details of a $10 million grant to research ways to combat state-sponsored spyware. The main issue is the capacity for abuse. Standalone parental control apps can be abused and the permissions they require can be incredibly intrusive – not only for children but in relation to anyone’s privacy.  A balance between a right to privacy and protection has to be maintained, and it’s a difficult tightrope to walk. Both Apple and Google have introduced parental controls for Android devices, Chromebooks, iPhones, and iPads. These platforms focus on restricting screen time, locking and unlocking devices, and features such as permissions list management, restricting web content and app downloads, and purchase approvals.